Impact
An out‑of‑bounds read in the Windows Storage Port Driver can be triggered by an authorized local attacker, allowing the attacker to read memory beyond the bounds of the intended buffer. This can disclose sensitive data from kernel or user space memory and potentially lead to further compromise. The weakness is identified as CWE‑125.
Affected Systems
The vulnerability affects multiple Microsoft Windows products including Windows 10 versions 1607, 1809, 21H2 and 22H2, Windows 11 versions 23H2, 24H2, 25H2 and 26H1, as well as Windows Server editions from 2012 through 2025. Affected builds span both 32‑ and 64‑bit architectures and ARM64 devices. The issue is present in the core operating system components that manage storage ports.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate risk, and no EPSS value is available, so the likelihood of exploitation is uncertain. Because the flaw requires local privilege, an attacker would need to be authenticated to the affected machine, making it a local information‑disclosure scenario. The vulnerability is not listed in CISA’s KEV catalog, and no known active exploits have been reported at this time.
OpenCVE Enrichment